By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Cisco ASA/FTD Flaw Exploited, Causing Remote DoS

Cisco has issued a critical warning regarding a newly identified vulnerability that is already being exploited in the wild, affecting its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This high-severity flaw, officially designated as CVE-2026-20349, carries a Common Vulnerability Scoring System (CVSS) score of 8.6, indicating a significant risk. The vulnerability stems from insufficient error checking mechanisms within the software when processing Hypertext Transfer Protocol (HTTP) requests. This oversight could permit an unauthenticated, remote attacker to exploit the flaw and initiate a denial-of-service (DoS) condition.
A denial-of-service attack aims to disrupt the normal functioning of a network, server, or service by overwhelming it with traffic or requests, rendering it inaccessible to legitimate users. In this specific instance, the attacker would not require any prior authentication to leverage the vulnerability. The exploitation of CVE-2026-20349 could lead to the affected device becoming unresponsive, requiring a manual reboot to restore service. Cisco has confirmed that the vulnerability has been observed in active exploitation, underscoring the urgency for users to implement mitigation measures.
The affected software versions include ASA Software versions 9.16(1) through 9.16(4) and FTD Software versions 7.0(1) through 7.2(5). Cisco's advisory provides specific details on the affected software releases, enabling customers to identify whether their deployments are at risk. The company has released software updates that address this vulnerability, and users are strongly advised to upgrade to the patched versions as soon as possible to protect their networks. The advisory also outlines workarounds that can be implemented if immediate patching is not feasible, although these are considered temporary solutions.
Cisco Secure Firewall ASA is a network security device that provides firewall, VPN, and intrusion prevention capabilities for enterprise networks. Secure Firewall FTD integrates multiple security services, including firewall, intrusion prevention, and advanced malware protection, into a single platform. The exploitation of this vulnerability could have significant implications for organizations relying on these Cisco security products to protect their network perimeters and sensitive data. The active exploitation in the wild suggests that threat actors are aware of the flaw and are actively seeking to compromise vulnerable systems. Organizations are urged to consult Cisco's official security advisory for detailed guidance on affected versions, mitigation steps, and the recommended software updates to remediate CVE-2026-20349.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.